Microsoft Windows 10 21H2 vulnerabilities
1,827 known vulnerabilities affecting microsoft/windows_10_21h2.
Total CVEs
1,827
CISA KEV
87
actively exploited
Public exploits
54
Exploited in wild
97
Severity breakdown
CRITICAL44HIGH1303MEDIUM473LOW7
Vulnerabilities
Page 50 of 92
CVE-2026-27921P3HIGHCVSS 7.0fixed in 10.0.19044.71842026-04-14
CVE-2026-27921 [HIGH] CWE-362 CVE-2026-27921: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54099P3HIGHCVSS 7.0fixed in 10.0.19044.63322025-09-09
CVE-2025-54099 [HIGH] CWE-121 CVE-2025-54099: Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized at
Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26635P3MEDIUMCVSS 6.5fixed in 10.0.19044.57372025-04-08
CVE-2025-26635 [MEDIUM] CWE-1390 CVE-2025-26635: Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over
Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
nvd
CVE-2022-35743P3HIGHCVSS 7.8fixed in 10.0.19044.18892023-05-31
CVE-2022-35743 [HIGH] CWE-94 CVE-2022-35743: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
nvd
CVE-2025-21220P3HIGHCVSS 7.5fixed in 10.0.19044.53712025-01-14
CVE-2025-21220 [HIGH] CWE-908 CVE-2025-21220: Microsoft Message Queuing Information Disclosure Vulnerability
Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2023-36710P3HIGHCVSS 7.8fixed in 10.0.19041.35702023-10-10
CVE-2023-36710 [HIGH] CWE-197 CVE-2023-36710: Windows Media Foundation Core Remote Code Execution Vulnerability
Windows Media Foundation Core Remote Code Execution Vulnerability
nvd
CVE-2023-36438P3HIGHCVSS 7.5fixed in 10.0.19041.35702023-10-10
CVE-2023-36438 [HIGH] CVE-2023-36438: Windows TCP/IP Information Disclosure Vulnerability
Windows TCP/IP Information Disclosure Vulnerability
nvd
CVE-2023-36393P3HIGHCVSS 7.8fixed in 10.0.19041.36932023-11-14
CVE-2023-36393 [HIGH] CWE-426 CVE-2023-36393: Windows User Interface Application Core Remote Code Execution Vulnerability
Windows User Interface Application Core Remote Code Execution Vulnerability
nvd
CVE-2024-30073P3HIGHCVSS 7.8fixed in 10.0.19044.48942024-09-10
CVE-2024-30073 [HIGH] CWE-41 CVE-2024-30073: Windows Security Zone Mapping Security Feature Bypass Vulnerability
Windows Security Zone Mapping Security Feature Bypass Vulnerability
nvd
CVE-2023-36905P3HIGHCVSS 7.5fixed in 10.0.19044.33242023-08-08
CVE-2023-36905 [HIGH] CWE-125 CVE-2023-36905: Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
nvd
CVE-2024-21442P3HIGHCVSS 7.8fixed in 10.0.19044.41702024-03-12
CVE-2024-21442 [HIGH] CWE-170 CVE-2024-21442: Windows USB Print Driver Elevation of Privilege Vulnerability
Windows USB Print Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38034P3HIGHCVSS 7.8fixed in 10.0.19044.46512024-07-09
CVE-2024-38034 [HIGH] CWE-190 CVE-2024-38034: Windows Filtering Platform Elevation of Privilege Vulnerability
Windows Filtering Platform Elevation of Privilege Vulnerability
nvd
CVE-2023-23420P3HIGHCVSS 7.8fixed in 10.0.19044.27282023-03-14
CVE-2023-23420 [HIGH] CWE-416 CVE-2023-23420: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-26238P3HIGHCVSS 7.8fixed in 10.0.19044.44122024-05-14
CVE-2024-26238 [HIGH] CWE-59 CVE-2024-26238: Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability
Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability
nvd
CVE-2024-21436P3HIGHCVSS 7.8fixed in 10.0.19044.41702024-03-12
CVE-2024-21436 [HIGH] CWE-284 CVE-2024-21436: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2023-29366P3HIGHCVSS 7.8fixed in 10.0.19044.30872023-06-14
CVE-2023-29366 [HIGH] CWE-415 CVE-2023-29366: Windows Geolocation Service Remote Code Execution Vulnerability
Windows Geolocation Service Remote Code Execution Vulnerability
nvd
CVE-2024-20658P3HIGHCVSS 7.8fixed in 10.0.19044.39302024-01-09
CVE-2024-20658 [HIGH] CWE-125 CVE-2024-20658: Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
nvd
CVE-2024-20681P3HIGHCVSS 7.8fixed in 10.0.19044.39302024-01-09
CVE-2024-20681 [HIGH] CWE-416 CVE-2024-20681: Windows Subsystem for Linux Elevation of Privilege Vulnerability
Windows Subsystem for Linux Elevation of Privilege Vulnerability
nvd
CVE-2023-36705P3HIGHCVSS 7.8fixed in 10.0.19041.36932023-11-14
CVE-2023-36705 [HIGH] CWE-59 CVE-2023-36705: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2024-26237P3HIGHCVSS 7.8fixed in 10.0.19044.42912024-04-09
CVE-2024-26237 [HIGH] CWE-416 CVE-2024-26237: Windows Defender Credential Guard Elevation of Privilege Vulnerability
Windows Defender Credential Guard Elevation of Privilege Vulnerability
nvd